CVE-2025-59715: Smseagle

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

SMSEagle before 6.11 allows reflected XSS via a username or contact phone number.

Affected products

  • Smseagle Smseagle: before 6.11 (fixed in 6.11)

Published 2025-09-19. Last modified 2026-06-17.